High severity7.3NVD Advisory· Published Mar 21, 2024· Updated Jun 17, 2026
CVE-2024-28123
CVE-2024-28123
Description
Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will arise if the host calls or resumes a Wasm function with more parameters than the default limit (128), as it will surpass the stack value. This doesn’t affect calls from Wasm to Wasm, only from host to Wasm. This vulnerability was patched in version 0.31.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wasmicrates.io | >= 0.15.0, < 0.31.1 | 0.31.1 |
Affected products
3cpe:2.3:a:wasmi-labs:wasmi:*:*:*:*:*:rust:*:*+ 1 more
- cpe:2.3:a:wasmi-labs:wasmi:*:*:*:*:*:rust:*:*range: >=0.15.0,<0.31.1
- (no CPE)range: >= 0.15.0, <= 0.31.0
Patches
Vulnerability mechanics
References
5- github.com/wasmi-labs/wasmi/commit/f7b3200e9f3dc9e2cbca966cb255c228453c792fnvdPatchWEB
- github.com/advisories/GHSA-75jp-vq8x-h4cqghsaADVISORY
- github.com/wasmi-labs/wasmi/security/advisories/GHSA-75jp-vq8x-h4cqnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-28123ghsaADVISORY
- github.com/wasmi-labs/wasmi/releases/tag/v0.31.1nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.